|
|
| |
|
| |
squid: denial of service
| Package(s): | squid |
CVE #(s): | CVE-2010-2951
|
| Created: | October 27, 2011 |
Updated: | November 2, 2011 |
| Description: |
From the CVE entry:
dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set. |
| Alerts: |
|
( Log in to post comments)
|
|
|